MALICIOUS — 49be48_4036e61d962f47b2a3e30e7f6edd3bfe.pdf
MALICIOUS — 49be48_4036e61d962f47b2a3e30e7f6edd3bfe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c83c08f4b7ce7644aeea10d48134d29eda57ae18497a1b6fc7392ac0fe6c37d0 - SHA-1:
baa144d75d0dc1908953a9235ae9bc0470f230a7 - MD5:
dd8626fa84c1c063072eb69110be597d - ssdeep:
768:RgGzpDs/HoyBZBqDdcdEyyCGQ2gzMSOzamW6Exykn+fsrVDbWnAl3QmG:iGFo/MjXLO6WyYcYGnAl3QmG - TLSH:
T1B3319EF35057ED8C368BDF13AEAB115A6186D6C921369A64458C3B6CC0BC7FC7E10861 - Submitted as: 49be48_4036e61d962f47b2a3e30e7f6edd3bfe.pdf
- File type: pdf · Size: 41906 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ttraff.club/wix?keyword=family+resource+center+el+cajon+ca, http://kobimej.lousrenew.com/uploads/1/3/2/6/132681670/5951659.pdf, http://gadarebig.fionabelousz.com/uploads/1/3/1/4/131414019/07a62d39a0688d0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
1096 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- teams.cloud.microsoft
- outlook.office.com
- searchapp.bundleassets.example
- outlook.office365.com
- ntp.ubuntu.com
- 192.168.122.105
- 224.0.0.252
- 192.168.122.1
- 192.168.122.255
- 169.254.19.19
- 192.168.122.113
- 169.254.35.13
- 192.168.122.116
- 169.254.110.32
- 192.168.122.106
- 192.168.122.107
- 192.168.122.109
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ttraff.club/wix?keyword=family+resource+center+el+cajon+ca
- http://kobimej.lousrenew.com/uploads/1/3/2/6/132681670/5951659.pdf
- http://gadarebig.fionabelousz.com/uploads/1/3/1/4/131414019/07a62d39a0688d0.pdf
- http://mufoleko.thepuckcollection.com/uploads/1/3/1/3/131379230/boropopigit-fizedopatovub.pdf
- http://woruro.alanamariecheuvront.com/uploads/1/3/1/4/131438477/vegamadizom_banaji.pdf
- https://cdn.shopify.com/s/files/1/0437/2113/0152/files/converter_para_autocad_2017.pdf
- https://cdn.shopify.com/s/files/1/0436/6984/8217/files/bdc_general_anatomy_handbook.pdf
- https://cdn.shopify.com/s/files/1/0433/2588/2520/files/50527791784.pdf
- https://cdn.shopify.com/s/files/1/0433/8545/4757/files/carnatic_music_lessons_for_beginners.pdf
- https://cdn.shopify.com/s/files/1/0440/3278/6597/files/after_effects_complete_guide.pdf
- https://cdn.shopify.com/s/files/1/0450/0160/5278/files/matigoxuxurefapevidixate.pdf
- https://cdn.shopify.com/s/files/1/0440/4844/9686/files/pajog.pdf
- https://cdn.shopify.com/s/files/1/0434/5724/9430/files/47832762154.pdf
- https://cdn.shopify.com/s/files/1/0437/3564/6357/files/good_luck_chuck_english_subtitles.pdf
- https://cdn.shopify.com/s/files/1/0432/9468/7400/files/wawojogegurur.pdf
- https://5807444f-183d-4c21-b57f-b741411f4489.filesusr.com/ugd/ab922d_9ec3c6586c8847c892092cbfd4f17232.pdf?index=true
- https://39756a80-b82c-441c-80ae-4ea26c598ae1.filesusr.com/ugd/18574e_b5e6873b09c74b70941efb5035197848.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.club
- kobimej.lousrenew.com
- gadarebig.fionabelousz.com
- mufoleko.thepuckcollection.com
- woruro.alanamariecheuvront.com
- cdn.shopify.com
- 5807444f-183d-4c21-b57f-b741411f4489.filesusr.com
- 39756a80-b82c-441c-80ae-4ea26c598ae1.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report